Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us

Lean Security

Penetration Testing
AI Penetration Test
Web Application Penetration Test
Mobile Application Penetration Test
API Penetration Test
IoT Penetration Test
External Network Penetration Test
Strategic Advisory
Threat Modelling
Bespoke Threat Advisory Service
AI Red Teaming
Adversary Simulation (Red & Purple Teaming)
Knowledge Base
Prices
Company
About Us
Why Us
Partners
Blog
Contact Us
January 11, 2026
Lean Security Expert
The ToolShell Crisis: Why Your SharePoint ...

The Australian Cyber Security Centre has issued urgent warnings about actively exploited vulnerabilities in Microsoft SharePoint Server (CVE-2025-53770) that enable unauthenticated remote code execution. With Chinese state-aligned actors and ransomware groups already compromising Australian organisations, this threat represents an immediate and severe risk to business-critical data and infrastructure.

The ToolShell Crisis: Why Your SharePoint Server Is a Ticking Time Bomb
December 27, 2025
Lean Security Expert
Why Long-Lived Cloud Credentials Are Your ...

Across AWS, Google Cloud, and Microsoft Azure environments in Australia and globally, 59% of IAM users maintain access keys that have never expired—credentials that have been active for more than one year. These long-lived credentials represent a silent but catastrophic vulnerability in your cloud infrastructure. This blog explores why long-lived credentials have become the primary attack vector for identity-based breaches, how red teams exploit them during penetration tests, and what you must do today to eliminate this ticking time bomb.

Why Long-Lived Cloud Credentials Are Your Biggest Identity Risk in 2025
December 21, 2025
Lean Security Expert
Fortinet "Ghost Logins": How Authentication ...

Critical authentication bypass vulnerabilities in Fortinet FortiGate and related products (CVE-2025-59718 and CVE-2025-59719) are now under active attack, allowing "ghost" SSO logins that completely sidestep normal controls and logs. For Australian organisations, this is more than a VPN or firewall problem – it is a board-level exposure that directly tests whether your external penetration testing, internal penetration testing, and red team assessment services are capable of simulating SSO abuse, identity takeovers, and lateral movement across hybrid networks.

Fortinet "Ghost Logins": How Authentication Bypass Attacks Expose Gaps in Your Penetration Testing Strategy
December 6, 2025
Lean Security Expert
React2Shell: A CISO’s Guide to CVE-2025-55182

A new security flaw called React2Shell (CVE-2025-55182) puts Australian businesses at extreme risk. It has a severity score of CVSS 10.0, which is the highest possible rating. This flaw lets hackers take full control of your servers without needing a password. It affects the popular tools React and Next.js.

React2Shell: A CISO’s Guide to CVE-2025-55182
November 26, 2025
Lean Security Expert
SessionReaper & BFCM: Why Penetration ...

A critical vulnerability in Adobe Commerce and Magento (CVE-2025-54236), dubbed "SessionReaper," is being ruthlessly exploited by threat actors using AI-driven tools to automate attacks at machine speed. With the Australian holiday trading season in full swing, this unauthenticated remote code execution (RCE) flaw poses an immediate existential threat to retail and B2B organizations. This alert outlines the mechanics of the attack, the role of AI in its weaponization, and the urgent defensive actions required to prevent a catastrophic data breach.

SessionReaper & BFCM: Why Penetration Testing Services Are Critical (CVE-2025-54236)
Lean Security Expert
November 13, 2017

Why Usability Testing Is So Important

Lean Security Expert
November 13, 2017
Why Usability Testing Is So Important

When it comes to sales, ‘Always be closing’ is the ultimate lesson. In the digital world, however, the mantra is ‘Always be testing’.

Comment
Lean Security Expert
November 8, 2017

Social Media Security – Some Common Threats

Lean Security Expert
November 8, 2017
Social Media Security – Some Common Threats

In the past few years, social media has become a phenomenon. The power of social media has been so impactful that it has completely revolutionised the way the human species communicated.

Comment
Lean Security Expert
November 4, 2017

Mobile App Vulnerabilities You Should Keep In Mind

Lean Security Expert
November 4, 2017
Mobile App Vulnerabilities You Should Keep In Mind

Although the incredible rise of mobile phone technology has revolutionised communications, it has also brought about massive security challenges.

Comment
Lean Security Expert
October 31, 2017

5 Trends to Watch Out For in Cyber Security!

Lean Security Expert
October 31, 2017
5 Trends to Watch Out For in Cyber Security!

From Cloudbleed to WannaCry, 2017 has already had its fair share of security breaches. With modern, sophisticated tactics employed by cyber criminals, it will take a lot to make the online world a safer place.

Comment
Lean Security Expert
October 20, 2017

Data Breach- A Guide For Mitigating The Risks

Lean Security Expert
October 20, 2017
Data Breach- A Guide For Mitigating The Risks

To diminish security threats, evaluation of employee exit strategies and off-site data storage practices.

 

Comment
Lean Security Expert
October 16, 2017

Web Application Security Checklist 2017 – Are You Ready?

Lean Security Expert
October 16, 2017
Web Application Security Checklist 2017 – Are You Ready?

2018 is just around the corner. The year went by so fast, bringing along with it new opportunities and possibilities regarding web application security.

Comment
Lean Security Expert
October 11, 2017

How Well Is The Security Testing In Your Organisation?

Lean Security Expert
October 11, 2017
How Well Is The Security Testing In Your Organisation?

With the growing number of breaches and online threats, it’s really surprising how many businesses fail to cater to their information security testing.

Comment
Lean Security Expert
October 7, 2017

How-to Improve Cyber Security For Non-Profit Organisations

Lean Security Expert
October 7, 2017
How-to Improve Cyber Security For Non-Profit Organisations

The number of businesses and organisations that have been hacked by cyber-criminals and malicious hackers just keeps increasing.

Cyber-security experts are scrambling here and there to cover all vulnerable holes within a framework – considering no organisation is safe from hackers.

Comment
Lean Security Expert
October 2, 2017
Network Security

Highlighting Open Source Software – How Detrimental It Is For Your Company

Lean Security Expert
October 2, 2017
Network Security
Highlighting Open Source Software – How Detrimental It Is For Your Company

Like many businesses looking to increase productivity and efficiency without shelling out the extra bucks, you also must have thought about exploring the world of open source software.

Comment
Lean Security Expert
August 25, 2017

Infographic: Five Most Common Security Concerns Businesses Face Today

Lean Security Expert
August 25, 2017

From untested system to exposed source, read five most common security concerns businesses face today

Comment
Newer Posts
Older Posts
Contact us for a quote
Back to Top
Lean Security, 81-83 Campbell Street, Surry Hills, NSW, 2010, Australia+61 (2) 8078 6952info@leansecurity.com.au

About Lean Security

We are a specialist cybersecurity firm based in Sydney, focusing on penetration testing. We partner with organisations across Australia, providing expert-led testing and clear, actionable reports. Our goal is to give you the clarity and confidence needed to secure your digital assets.

     
Useful Links
Home
Application penetration testing
Security source code assessment
Mobile application penetration testing
Infrastructure penetration testing
API web services penetration testing
Threat Modelling Service

Newsletter

We respect your privacy.

Thank you!

Contact Us

Phone: +61 (2) 8078 6952
Email: info@leansecurity.com.au

Monday - Friday from 9.00 am to 8.00 pm
Saturday from 10.00 am to 6.00 pm